Three separate McAfee Advanced Threat Defense (MATD) vulnerabilities have been reported and patched.
Configuration Information: The MATD appliance web interface is showing configuration information in plain text format.
Authentication Enforcement: The MATD web interface has loose enforcement of authentication and authorization which leads to information disclosure.
Privilege Escalation: The MATD appliance allows the administrator only to change/update any configuration settings, but in some instances an unprivileged user can manipulate some parameters to gain administrator functionality.